PT-2016-2581 · Microsoft · Office+5
Published
2016-08-09
·
Updated
2018-10-12
·
CVE-2016-3304
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fixed version
Microsoft Office versions prior to the fixed version
Word Viewer version not specified
Skype for Business version not specified
Live Meeting version not specified
Microsoft Lync versions prior to the fixed version
Description
The issue exists due to insufficient input validation in the Windows font library. This allows a remote attacker to execute arbitrary code using a specially crafted embedded font. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations
For Microsoft Windows, update to the latest version to resolve the issue.
For Microsoft Office, update to the latest version to resolve the issue.
For Word Viewer, Skype for Business, Live Meeting, and Microsoft Lync, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of embedded fonts in these applications to minimize the risk of exploitation.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Live Meeting
Lync
Office
Skype For Business
Windows
Word Viewer